VYPR
High severity8.8NVD Advisory· Published Jan 13, 2026· Updated Apr 13, 2026

CVE-2026-0880

CVE-2026-0880

Description

Sandbox escape due to integer overflow in the Graphics component. This vulnerability was fixed in Firefox 147, Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7.

Affected products

4
  • cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*+ 1 more
    • cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*range: <115.32.0
    • cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:*range: <147.0
  • cpe:2.3:a:mozilla:thunderbird:*:*:*:*:esr:*:*:*+ 1 more
    • cpe:2.3:a:mozilla:thunderbird:*:*:*:*:esr:*:*:*range: <140.7.0
    • cpe:2.3:a:mozilla:thunderbird:*:*:*:*:-:*:*:*range: <147.0

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

6

News mentions

0

No linked articles in our index yet.